Requirement 9: Restrict Physical Access to Cardholder Data

PCI DSS v4.0.1 Requirement 9: facility access controls, media handling, and the POI device inspection routine that catches skimmers.

Requirement 9 is often skimmed by cloud-hosted entities, but it rarely falls away entirely. Media, devices and offices remain in scope even when servers do not.

PCI DSS v4.0.1 breaks this requirement into 5 sections containing 26 individual controls.

What this requirement is actually asking

If you take card-present payments, 9.5.1 is the control that matters most: point-of-interaction devices are inspected periodically for tampering and substitution, and personnel are trained to spot it. This is the physical counterpart to 6.4.3.

9.4 covers media across its whole life. Classification, secure storage, controlled distribution, and destruction so that data cannot be reconstructed. Cross-cut shredding and certificates of destruction are the usual evidence.

Does it apply to you?

Any facility housing in-scope systems, media or POI devices. Fully cloud-hosted entities with no card-present channel may scope much of this out, with justification.

The controls

Requirement 9 contains 26 controls across 5 sections. Each links to its own page with the requirement in full and the testing procedures an assessor uses to verify it.

9.1: Governance for physical access restriction

Control What it requires Guidance
9.1.1 All security policies and operational procedures that are identified in Requirement 9… Yes
9.1.2 Roles and responsibilities for performing activities in Requirement 9 are documented, assigned… Yes

9.2: Facility entry controls and monitoring

Control What it requires Guidance
9.2.1 Appropriate facility entry controls are in place to restrict physical access to systems… Yes
9.2.1.1 Individual physical access to sensitive areas within the CDE is monitored with either video… Yes
9.2.2 Physical and/or logical controls are implemented to restrict use of publicly accessible network… Yes
9.2.3 Physical access to wireless access points, gateways, networking/communications hardware… Yes
9.2.4 Access to consoles in sensitive areas is restricted via locking when not in use Yes

9.3: Authorising personnel and visitors, including badge return

Control What it requires Guidance
9.3.1 Procedures are implemented for authorizing and managing physical access of personnel… Yes
9.3.1.1 Physical access to sensitive areas within the CDE for personnel is controlled… Yes
9.3.2 Procedures are implemented for authorizing and managing visitor access to the CDE… Yes
9.3.3 Visitor badges or identification are surrendered or deactivated before visitors leave… Yes
9.3.4 Visitor logs are used to maintain a physical record of visitor activity both within… Yes

9.4: Media: storage, distribution, retention and destruction

Control What it requires Guidance
9.4.1 All media with cardholder data is physically secured Yes
9.4.1.1 Offline media backups with cardholder data are stored in a secure location Yes
9.4.1.2 The security of the offline media backup location(s) with cardholder data is reviewed at least… Yes
9.4.2 All media with cardholder data is classified in accordance with the sensitivity of the data Yes
9.4.3 Media with cardholder data sent outside the facility is secured… Yes
9.4.4 Management approves all media with cardholder data that is moved outside the facility… Yes
9.4.5 Inventory logs of all electronic media with cardholder data are maintained Yes
9.4.5.1 Inventories of electronic media with cardholder data are conducted at least once every 12 months Yes
9.4.6 Hard-copy materials with cardholder data are destroyed when no longer needed for business… Yes
9.4.7 Electronic media with cardholder data is destroyed when no longer needed for business or legal… Yes

9.5: POI device protection against tampering and substitution

Control What it requires Guidance
9.5.1 POI devices that capture payment card data via direct physical interaction with the payment… Yes
9.5.1.1 An up-to-date list of POI devices is maintained… Yes
9.5.1.2 POI device surfaces are periodically inspected to detect tampering and unauthorized substitution Yes
9.5.1.3 Training is provided for personnel in POI environments to be aware of attempted tampering… Yes

Evidence your assessor will ask for

  • Visitor logs retained for at least three months (9.3.4)
  • A POI device inventory with make, model, serial and location, plus dated inspection records
  • Media destruction certificates
  • Badge access reports showing revocation on termination

Where this commonly fails

  • A POI inventory that exists but has no inspection records against it
  • Backup media taken offsite by an untracked courier
  • Assuming a data centre provider's SOC 2 covers this without obtaining the responsibility matrix

Official source

This page is original commentary. It cites requirement identifiers and the official requirement title, and does not reproduce the text of the standard. For the authoritative wording, including each testing procedure and the customized approach objective, download PCI DSS v4.0.1 (June 2024) from the PCI Security Standards Council document library.

PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site.